HeadlinesBriefing favicon HeadlinesBriefing.com

Iran-linked STORM-0817 used AI for malware

OpenAI Blog •
×

OpenAI has identified and banned accounts linked to Iran-based threat actor STORM-0817, who utilized AI models for malicious activities. This marks the first public identification of this actor employing AI.

STORM-0817 leveraged OpenAI's models for debugging Android malware, coding assistance to create an Instagram scraper, and translating LinkedIn profiles into Persian. The malware, targeting Android, possessed surveillance capabilities, including retrieving contacts, call logs, installed packages, media, screenshots, device information, browsing history, location, and files from external storage. The actor used this code in two Android packages: com.example.myttt and com.mihanwebmaster.ashpazi.

Furthermore, STORM-0817 sought help to develop server-side code for command and control infrastructure, identified as a WAMP setup using the domain stickhero[.]pro during testing. They also used AI to debug code for scraping Instagram profiles and to translate LinkedIn profiles of individuals associated with Pakistan's National Center for Cyber Security, aligning with reconnaissance efforts targeting Pakistani military-affiliated institutions. OpenAI disabled the identified accounts and shared indicators of compromise with industry partners, noting that AI offered limited, incremental capabilities for these tasks.